This Privacy Policy explains what personal data willhub.io Ltd (“we”) collects, how we use it, and your rights. It applies to firms that subscribe to willhub.io and to clients whose data those firms store in the platform.
1. Data we collect. From firm users: name, email, job title, phone, firm name, and authentication identifiers. From clients (entered by firm users): contact details, factfind information, communications history, and any documents you choose to upload.
2. How we use it. We process firm-user data to provide the service, authenticate you, send service emails, and bill your subscription. Client data is processed strictly on the firm’s instructions; we are a processor under UK GDPR and the firm is the controller.
3. Sub-processors. We use Clerk (authentication), Stripe (payments), Resend (transactional email), Twilio (SMS/WhatsApp), and a UK/EU-hosted PostgreSQL database. Each provider is bound by a data processing agreement.
4. Retention. Firm-user data is kept while your account is active and for 30 days after cancellation, after which it is deleted. Client data is kept as long as the firm requires and is deleted on the firm’s instructions.
5. Your rights. You can access, correct, export, or delete your data at any time from your account settings or by emailing privacy@willhub.io. You also have the right to lodge a complaint with the ICO.
6. International transfers. We host data in the UK/EU. If a sub-processor transfers data outside the UK/EU we rely on standard contractual clauses.
7. Cookies. We use only essential cookies (sign-in session, CSRF protection). No advertising or analytics cookies are set.
This is a placeholder draft (v1) issued on 2026-05-27. The final policy will be published before paid plans go live.